Staff accounts with two-factor authentication
WHMCS publishes no supported way to verify a staff second factor from outside its own login form. Checking only the password would make this app the easy way past a control you deliberately switched on, so accounts with two-factor cannot sign in to the app with a password at all. They sign in with a passkey, which is possession of the phone plus a fingerprint or face, and is a second factor in its own right. Enrolment starts on the Security screen in WHMCS, where you have already satisfied the second factor: it mints a link that works once, for ten minutes, for your account only. Scan it with the phone you want to sign in from. Treat the link like a password until it is used, because anyone holding it can add a passkey to your account. There is a setting to allow password sign-in for these accounts anyway. It is off, and it should stay off.